Microsoft Certified: Identity and Access Administrator AssociateImplement an identity management solutionMedium
A company is deploying Azure AD Connect to synchronize user accounts from an on-premises Active Directory. They have a complex OU structure and only want to synchronize users located in OUs named 'Sales' and 'Marketing' within a specific domain, 'contoso.com'. Users in other OUs, even within 'contoso.com', or in other domains/forests, should not be synchronized. Which synchronization filtering method should be configured in Azure AD Connect?
- AAttribute-based filtering
- BOrganizational Unit (OU) filtering
- CDomain-based filtering
- DGroup-based filtering
Show answer & explanationAnswer & explanation
Correct answer: B. Organizational Unit (OU) filtering
Organizational Unit (OU) filtering in Azure AD Connect allows administrators to select specific OUs from their on-premises Active Directory to be synchronized to Azure AD, precisely matching the requirement to sync only users in 'Sales' and 'Marketing' OUs.
Why the other options are wrong
- A. Attribute-based filtering uses user attributes (e.g., department) but is less direct for OU-specific requirements.
- C. Domain-based filtering synchronizes entire domains, not specific OUs within a domain.
- D. Group-based filtering synchronizes members of specified groups, which would require managing group memberships, not OUs.
Azure AD Connect OU Filtering
A feature in Azure AD Connect that allows administrators to selectively synchronize objects based on their Organizational Unit (OU) location in the on-premises Active Directory to Azure AD.
- Configured during initial setup or later via wizard.
- Excludes or includes entire OUs.
- Useful for managing scope of synchronized identities.
Memory trick: Filter the forest, only sync the chosen branches.